Vulnerabilities > Redhat > Keycloak > 15.1.1

DATE CVE VULNERABILITY TITLE RISK
2022-08-23 CVE-2021-3827 Improper Authentication vulnerability in Redhat Keycloak and Single Sign-On
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed.
network
high complexity
redhat CWE-287
6.8
2022-07-08 CVE-2022-1245 Authorization Bypass Through User-Controlled Key vulnerability in Redhat Keycloak
A privilege escalation flaw was found in the token exchange feature of keycloak.
network
low complexity
redhat CWE-639
critical
9.8
2022-04-26 CVE-2022-1466 Incorrect Authorization vulnerability in Redhat Keycloak
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform.
network
low complexity
redhat CWE-863
6.5
2022-03-25 CVE-2021-20323 Cross-site Scripting vulnerability in Redhat Keycloak
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
network
low complexity
redhat CWE-79
6.1